Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 332

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
SpaceX gives Nvidia a much-needed boost. Plus, Cramer on an 'undervalued' stock
Oil prices fall on negotiations to manage ship traffic in Strait of Hormuz
Movie: The Egg and I
Salad and Go files for Chapter 11 bankruptcy after cyclospora fears worsened its challenges
Google chief scientist Jeff Dean leaving in AI reshuffle after 27 years at company
Ken Griffin's Citadel posts best month in years after scooping up Situational Awareness stocks
Phone storage driving me loco
Disney tops earnings estimates as parks and streaming offer a boost
SpaceX's earnings are not helping its stock, but Nvidia is getting a boost
Tales from the Crypt: The Man Who Was Death